<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: (Fix) r3953724.cn Malware/Adware Redirections</title>
	<atom:link href="http://www.fencepost.net/2009/10/investigating-r3953724-cn-malwareadware-redirections/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fencepost.net/2009/10/investigating-r3953724-cn-malwareadware-redirections/</link>
	<description>Thoughts &#38; Resources on IT Consulting for Small Medical Practices</description>
	<lastBuildDate>Fri, 06 Jan 2012 06:39:33 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Propeller Head</title>
		<link>http://www.fencepost.net/2009/10/investigating-r3953724-cn-malwareadware-redirections/comment-page-1/#comment-421</link>
		<dc:creator>Propeller Head</dc:creator>
		<pubDate>Fri, 30 Oct 2009 04:25:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.fencepost.net/?p=292#comment-421</guid>
		<description>You&#039;re very welcome guys - glad I could help!  8^)</description>
		<content:encoded><![CDATA[<p>You&#8217;re very welcome guys &#8211; glad I could help!  8^)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan</title>
		<link>http://www.fencepost.net/2009/10/investigating-r3953724-cn-malwareadware-redirections/comment-page-1/#comment-420</link>
		<dc:creator>Alan</dc:creator>
		<pubDate>Fri, 30 Oct 2009 02:42:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.fencepost.net/?p=292#comment-420</guid>
		<description>Agreed, kudos to Propellor Head - I had seen atapi.sys show up on something in a scan - HijackThis perhaps - but hadn&#039;t paid any attention to it because it was in the right place, with the right name, and I was working with CD-based files since I couldn&#039;t download directly.</description>
		<content:encoded><![CDATA[<p>Agreed, kudos to Propellor Head &#8211; I had seen atapi.sys show up on something in a scan &#8211; HijackThis perhaps &#8211; but hadn&#8217;t paid any attention to it because it was in the right place, with the right name, and I was working with CD-based files since I couldn&#8217;t download directly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Grateful_Reader</title>
		<link>http://www.fencepost.net/2009/10/investigating-r3953724-cn-malwareadware-redirections/comment-page-1/#comment-419</link>
		<dc:creator>Grateful_Reader</dc:creator>
		<pubDate>Thu, 29 Oct 2009 21:03:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.fencepost.net/?p=292#comment-419</guid>
		<description>Thanks a million, Propeller Head -- that did the trick! How the heck did you figure this out?

Mad props, my friend. =)</description>
		<content:encoded><![CDATA[<p>Thanks a million, Propeller Head &#8212; that did the trick! How the heck did you figure this out?</p>
<p>Mad props, my friend. =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Propeller Head</title>
		<link>http://www.fencepost.net/2009/10/investigating-r3953724-cn-malwareadware-redirections/comment-page-1/#comment-418</link>
		<dc:creator>Propeller Head</dc:creator>
		<pubDate>Thu, 29 Oct 2009 13:30:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.fencepost.net/?p=292#comment-418</guid>
		<description>It&#039;s a rootkit in atapi.sys.  I successfully cleaned my infection last night.  Use the newest version of ComboFix - it detects and cleans it.  Make sure you allow it to install the recovery console if it&#039;s not already resident.  Good luck!</description>
		<content:encoded><![CDATA[<p>It&#8217;s a rootkit in atapi.sys.  I successfully cleaned my infection last night.  Use the newest version of ComboFix &#8211; it detects and cleans it.  Make sure you allow it to install the recovery console if it&#8217;s not already resident.  Good luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan</title>
		<link>http://www.fencepost.net/2009/10/investigating-r3953724-cn-malwareadware-redirections/comment-page-1/#comment-416</link>
		<dc:creator>Alan</dc:creator>
		<pubDate>Thu, 29 Oct 2009 03:20:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.fencepost.net/?p=292#comment-416</guid>
		<description>I&#039;ve left it with Kaspersky&#039;s boot CD scanning to see if it&#039;ll pick anything up. It doesn&#039;t seem to be actively going out, but when you use the browser it does redirect. 
I&#039;ve left a note for the users in the office to not use it, because not all of the redirects are failing - some are going to a variety of hacked sites, which then redirect to advertising or malware (one of those redirects to a malware site was caught by AVG).</description>
		<content:encoded><![CDATA[<p>I&#8217;ve left it with Kaspersky&#8217;s boot CD scanning to see if it&#8217;ll pick anything up. It doesn&#8217;t seem to be actively going out, but when you use the browser it does redirect.<br />
I&#8217;ve left a note for the users in the office to not use it, because not all of the redirects are failing &#8211; some are going to a variety of hacked sites, which then redirect to advertising or malware (one of those redirects to a malware site was caught by AVG).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rod I</title>
		<link>http://www.fencepost.net/2009/10/investigating-r3953724-cn-malwareadware-redirections/comment-page-1/#comment-415</link>
		<dc:creator>Rod I</dc:creator>
		<pubDate>Thu, 29 Oct 2009 03:01:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.fencepost.net/?p=292#comment-415</guid>
		<description>I have the same issue. For now, I have the local loopback in host file pointed to r3953724.cn to avoid the google redirect.
Malware, CA AV, CA PP not detecting anything. IE Addons disabled as well.</description>
		<content:encoded><![CDATA[<p>I have the same issue. For now, I have the local loopback in host file pointed to r3953724.cn to avoid the google redirect.<br />
Malware, CA AV, CA PP not detecting anything. IE Addons disabled as well.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

